Remote Code Execution in Liferay Portal and Liferay DXP Products
CVE-2025-3586
What is CVE-2025-3586?
In specific versions of Liferay Portal and Liferay DXP, the Objects module fails to restrict Groovy scripts for Admin Users, enabling remote authenticated administrators to execute arbitrary code. This vulnerability poses significant security risks as it allows for unauthorized execution of scripts, potentially compromising the integrity of the affected systems. In contrast, Liferay DXP configurations do not permit Groovy in Object actions, highlighting the importance of version management and security settings.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
DXP 7.4.13-u27 <= 7.4.13-u42
DXP 2023.Q3.1 <= 2023.Q3.10
DXP 2023.Q4.0 <= 2023.Q4.10
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved